IoT Application Authorization via Pre-Authenticated Network Contexts

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current interfaces between IoT devices and networks lack scalable mechanisms for authentication and authorization, leading to communication delays and inefficiencies between IoT devices, content providers, and network operators.

Innovation Solution

A method and apparatus for IoT device authentication and authorization that involves receiving a device authorization request with application-specific information, identifying the application, checking its authorization status, and transmitting an authorization approval containing application-specific information, facilitating efficient information transfer and reducing the need for repeated authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If current interfaces between IoT devices and networks are used for authentication and authorization, then device security is maintained, but communication delays increase and efficiency decreases

Engineering Contradiction:
Improveauthentication and authorization efficiencyVSAvoidcommunication delays
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by establishing authentication and authorization contexts before actual communication occurs. The network operator's network authentication function authenticates the IoT device and establishes an authentication context, while the content provider's authentication function simultaneously authorizes the device for specific content services. This preliminary authentication and authorization setup eliminates the need for repeated authentication checks during subsequent communications, thereby reducing communication delays and improving efficiency.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces intermediary authentication functions as mediators between IoT devices, network operators, and content providers. The network authentication function acts as an intermediary that handles device authentication, while the content provider authentication function serves as an intermediary for authorization decisions. These intermediary functions streamline the authentication and authorization process by centralizing the verification logic, reducing the overhead of repeated authentication checks, and enabling faster communication between all parties.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of manufacture

If traditional authentication mechanisms are used, then security is maintained, but operating expenses increase

Engineering Contradiction:
Improveoperating expense efficiencyVSAvoidauthentication security
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent applies universality by designing a multi-functional authentication system where the network authentication function performs both device authentication and authorization coordination, while the content provider authentication function handles both authorization verification and session management. This universal approach consolidates multiple authentication-related operations into single functions, reducing the number of separate systems needed and thereby lowering operating expenses while maintaining security through comprehensive authentication coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements self-service by enabling the authentication and authorization system to automatically manage its own operations. The authentication functions automatically verify device credentials, establish authentication contexts, and coordinate authorization decisions without requiring manual intervention. The system self-manages authentication state information and automatically handles subsequent communications, reducing operational overhead and expenses while maintaining reliable security through automated verification processes.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3987739B1Methods and apparatus for device authentication and authorisation
Publication Date: 2025.11.19 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP3987739B1 patent drawingFigure 1
  • EP3987739B1 patent drawingFigure 2
  • EP3987739B1 patent drawingFigure 3A

AI summary

A method and apparatus for device authentication and authorisation, wherein the method comprises: receiving, at an authentication and authorisation node, a device authorisation request comprising identity information for an application executed by a device and a first application specific container containing application specific information; identifying, using the device authorisation request, the application to which the request relates, and checking the authorisation status of the application; if the application is authorised for use, transmitting an authorisation approval, the authorisation approval comprising the first application specific container containing application specific information.